---
search:
  tags:
    - Workspace
    - POST
seo:
  description: >-
    Unauthenticated exchange: the one-time code plus PKCE verifier is the…
    Reference for the POST /v1/cli-login/exchange endpoint in the openlaunch
    API.
sidebar:
  label: Exchange CLI login code
  badge: POST
title: Exchange CLI login code
type: openapi-operation
---
Unauthenticated exchange: the one-time code plus PKCE verifier is the credential. Returns the agent connection token once, bound to the caller's workspace with a policy delegated from the parent principal (persistent ancestry enforced server-side). Owner review covers privilege amplification.

`POST /v1/cli-login/exchange`
